Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageDevSecOps Desk
DevSecOps

A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope

A dormant contributor account was hijacked to republish every package in the @mastra npm scope with an injected crypto-stealer dependency, illustrating how forgotten accounts with residual publish rights become the weakest link in scope ownership.

Summary written by editorial AI · Source link below

Filed by Snyk Blog1 min readRead at source ↗

A dormant contributor account was used to republish the entire @mastra npm scope, each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer. Here is how the attack worked, how to check exposure, and how to remediate.

Editorial Analysis

Why it matters

Dormant accounts with residual publishing permissions are a systemic blind spot; enterprise teams must treat contributor lifecycle management as a critical supply-chain control.

What to do

Review npm org membership for dormant or former contributor accounts with publish access, and enforce MFA plus periodic access recertification.

Board brief

An abandoned developer account was exploited to inject malware across an entire npm scope—dormant access rights are a supply-chain liability.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Snyk Blog

External link — opens at Snyk Blog in a new tab.

§
Continue with

More from the DevSecOps Desk